Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Meta Patches Muse Exploit that Allows Attackers to Control AI Agent


Meta has patched a zero-day vulnerability in its Muse AI agent that could allow attackers to control the AI. The vulnerability was discovered by security researcher Patrick Wardle and allows attackers to manipulate the agent and leverage its privileges to do whatever they want. Meta has issued a hotfix to address the issue, but the exploit has raised concerns about the security of the AI agent.

  • Meta issued a patch for its Muse macOS app after discovering a zero-day vulnerability.
  • A security researcher, Patrick Wardle, found the bug, which allowed attackers to take control of the AI agent.
  • The vulnerability was exploited by allowing any app to control Muse's undocumented settings.
  • Meta patched the issue within hours, stating that real-world security concerns were minimal due to the exploit requiring local access.
  • The Muse app's success comes amidst scrutiny of Meta's AI agent and rival AI providers.



  • Meta has issued a patch for its Muse macOS app following the discovery of a zero-day vulnerability that could allow someone to take control of the AI agent. The bug found by security researcher Patrick Wardle utilized an undocumented Muse setting that enabled potential attackers running local code to redirect transcription processing from Meta’s servers to their own endpoint, according to reports by Ars Technica.

    This flaw was reportedly enabled by several design decisions made by Meta, including having Muse dictation occur in the cloud instead of on-device, and allowing any app to control all of Muse’s undocumented settings. Proof-of-concept attacks developed by Wardle to test the exploit enabled him to take pictures and write malicious files to disk via Muse, which did not alert the user in many cases.

    According to Wardle, the vulnerability allowed attackers to manipulate the agent and leverage its privileges to do whatever they wanted. "We can manipulate the agent and leverage its privileges to do whatever we want. So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself," Wardle told Ars Technica.

    Meta patched the vulnerability in the hours following the Ars report being published, and asserts that real-world security concerns were minimal because the exploit required local access to the user’s device. "This was a local privilege escalation attack, not a remote exploit. Using it to do harm therefore requires malicious code already running on the user’s machine under their user account and the practical risk to users of the Muse Mac app was therefore quite low," David Singleton of Meta Superintelligence Labs said on X. "Nonetheless, we have issued a hotfix to the app to address the issue."

    The Muse exploit comes at a time when Meta’s AI agent is already being scrutinized as the company tries to claw back ground from rival AI providers. Amazon recently blocked Muse from accessing its e-commerce platform and claims Meta never obtained its permission to do so. Still, the launch has been successful for Meta — during its first 12 days, estimated downloads of the Muse mobile app have reportedly outpaced ChatGPT’s own 12-day debut in the US and Canada, with Meta stock climbing by 11 percent on Monday.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Meta-Patches-Muse-Exploit-that-Allows-Attackers-to-Control-AI-Agent-ehn.shtml

  • https://www.theverge.com/tech/998679/meta-muse-patch-zero-day-exploit-ai-agent


  • Published: Tue Sep 22 08:55:21 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us